Vulnerabilities

Summary — last 7 days

New vulnerabilities2,661▼ 437 vs. last week
Critical / high1,284▼ 85 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)247▼ 271 vs. last week
–

112 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9)1.6%—Rymera WEB CO PTY LTD Woocommerce Wholesale Lead CaptureAI3/19/20266/17/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.
DeferredCritical (9.3)0.43%—Kamleshyadav WP Lead CaptureAI1/22/20266/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through <= 2.5.
DeferredHigh (8.5)0.42%—Kamleshyadav WP Lead CaptureAI1/22/20266/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through <= 2.5.
AnalyzedMedium (6.9)0.14%—Milner Imagedirector Capture1/20/20266/17/2026
Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application encryption key. This issue affects ImageDirector Capture: from 7.0.9.0 before…
AnalyzedHigh (7.2)0.08%—Milner Imagedirector Capture1/20/20266/17/2026
Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability in the Password class in C2SConnections.dll in Milner ImageDirector Capture on Windows allows Encryption Brute Forcing to obtain database credentials.This issue affects ImageDirector Capture: from 7.0.9.0 before 7.6.3.25808.
AnalyzedHigh (8.5)0.18%—Milner Imagedirector Capture1/20/20266/17/2026
Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects…
AnalyzedHigh (8.5)0.19%—Milner Imagedirector Capture1/20/20266/17/2026
Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrieval of credential material and enables database access.This issue affects ImageDirector Capture: from 7.0.9 through 7.6.3.25808.
AnalyzedHigh (8.5)0.07%—Milner Imagedirector Capture1/20/20266/17/2026
The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable. This issue affects ImageDirector Capture: from 7.0.9 before…
DeferredMedium (4.3)0.13%—Winwar WP Email CaptureAI12/24/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery.This issue affects WP Email Capture: from n/a through <= 3.12.5.
AnalyzedMedium (6.1)0.29%—Clincapture Captivate Electronic Data Capture12/22/20256/17/2026
Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.
DeferredMedium (5.3)0.25%—Winwar WP Email CaptureAI12/9/20256/17/2026
Missing Authorization vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Email Capture: from n/a through <= 3.12.4.
AnalyzedHigh (7.8)0.23%—Electroncapture Electron Capture8/5/20256/17/2026
Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment variable allows arbitrary Node.js code to be executed via the -e…
DeferredMedium (4.3)0.17%—Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI5/7/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Cross Site Request Forgery.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.8.
DeferredHigh (7.1)0.29%—Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI4/17/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Reflected XSS.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.7.
DeferredMedium (6.5)0.18%—Recapture FOR WoocommerceAI3/15/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce recapture-for-woocommerce allows Cross Site Request Forgery.This issue affects Recapture for WooCommerce: from n/a through <= 1.0.43.
DeferredHigh (8.7)0.39%—Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI3/13/20256/17/2026
Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients.
DeferredCritical (9.3)0.45%—Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI3/13/20256/17/2026
Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that could allow an attacker to bypass authentication measures and gain controls over utilities within the products.
DeferredHigh (8.7)0.39%—Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI3/13/20256/17/2026
Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard coded secret key. This could allow an attacker to generate valid JWT (JSON Web Token) sessions.
DeferredMedium (4.3)0.25%—Wishfulthemes Email Capture AND Lead GenerationAI1/16/20256/17/2026
Missing Authorization vulnerability in wishfulthemes Email Capture & Lead Generation email-capture-lead-generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email Capture & Lead Generation: from n/a through <= 1.0.2.
DeferredMedium (4.3)0.31%—SMS FOR Lead Capture FormsAI12/7/20246/17/2026
The SMS for Lead Capture Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_message() function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
ModifiedMedium (5.9)0.30%—IBM Qradar Network Packet Capture8/15/20246/17/2026
IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
ModifiedMedium (5.5)0.21%—Sonicwall Capture ClientSonicwall Netextender1/18/20246/17/2026
SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability.
ModifiedMedium (5.4)0.34%—Tungstenautomation Kofax Capture1/11/20246/17/2026
The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnotation, where input data transmitted via the POST method in the parameters author and text are not adequately sanitized and validated. This allows for the injection of malicious JavaScript code. The…
ModifiedHigh (7.5)0.55%—Winwar WP Email Capture12/21/20236/17/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Marketing Plugin – WP Email Capture: from n/a through 3.10.
ModifiedCritical (9.8)1.5%—HP Laserjet Managed MFP E62665 3gy14a FirmwareHP Laserjet Managed MFP E62665 3gy15a FirmwareHP Laserjet Managed MFP E62665 3gy16a FirmwareHP Laserjet Managed MFP E62665 3gy17a Firmware+9536/14/20236/17/2026
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.